Fully Homomorphic Encryption Method, System, Device and Medium Applicable to Ciphertext Encryption

By adopting a fully homomorphic encryption method suitable for ciphertext encryption in the database, public and private key pairs are generated and data is encrypted and stored, the problem of low ciphertext retrieval efficiency is solved and efficient and secure data retrieval services are realized.

CN119788264BActive Publication Date: 2025-05-30GUANGZHOU TEC SOLUTIONS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510279252.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-11
Publication Date
2025-05-30
Estimated Expiration
2045-03-11

AI Technical Summary

Technical Problem

The prior art is difficult to provide efficient data retrieval services while ensuring data security. Especially in a ciphertext encryption environment, ciphertext retrieval becomes difficult and affects the user experience.

Method used

The lightweight all-homomorphic encryption method suitable for ciphertext encryption is adopted, and public-private key pairs are generated through a proxy server, data is encrypted and stored, and encrypted query statements are processed when needed, homomorphic calculations and decryption are performed to achieve efficient data retrieval.

Benefits of technology

It realizes providing efficient data retrieval services based on data encryption storage, reducing computing overhead, improving computing speed, and easy to implement, meeting users' dual needs for data security and retrieval efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119788264B_ABST
    Figure CN119788264B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of computer information security technology, and in particular to a fully homomorphic encryption method, system, device and medium suitable for ciphertext encryption. When an application server needs to query the sum or product of multiple fields or compare fields, a query request is initiated to a proxy server; the proxy server receives the request from the application server, encrypts the key fields of the user's query statement, and still ensures the grammatical requirements of the query statement, and sends the encrypted query statement to an encrypted database; the proxy server receives the ciphertext data returned from the terminal database, and performs addition, multiplication or comparison operations on the ciphertext data according to the query statement requirements, and decrypts the operation results and sends them to the application server. The fully homomorphic encryption method suitable for ciphertext encryption provided by the present invention only requires simple large integer operations, has the advantages of low computational overhead, fast computational speed and easy implementation, and realizes efficient data retrieval.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer information security, and particularly to a fully homomorphic encryption method, system, device and medium applicable to ciphertext encryption. Background Art

[0002] In today's information age, data has become the most precious resource. For individuals, data has the meaning of record retention, such as photos, videos, etc. For enterprise organizations, a large amount of data can help make better decisions. For example, travel companies can plan better travel routes for users. Data has become an inseparable part of people's daily lives. Usually, data is stored centrally. Many companies provide cloud storage technology, which can store users' data in cloud space. Its essence is database storage technology. Storing personal or enterprise data, especially privacy data, on a third-party server is not secure. Especially in recent years, continuous data leakage incidents have made people start to pay attention to data security. As a storage medium, the security of the database has also received extensive attention.

[0003] As a storage medium for data, the database stores a vast amount of data. Facing various network attacks and security threats, relying solely on traditional identity authentication mechanisms can no longer protect the security of user data well. Many scholars have started to study methods to improve data security. Among many research techniques, data encryption storage has become the most direct and effective means. Data encryption is to encrypt a meaningful plaintext sequence into a meaningless ciphertext sequence through an encryption algorithm and a key. If an attacker obtains relevant ciphertext information, without the decryption key and unknown encryption algorithm, they cannot obtain any useful information about the original data. This method greatly improves the security of user data.

[0004] Data encryption storage can solve the security problem, but as information, data has random access, that is, it may be accessed by users at any time. Before data encryption, it has many attributes, such as the size comparability and orderliness of numerical data, and information such as key characters of character data. These attributes support many retrieval methods of plaintext data. The encryption operation destroys the original data attributes, making many operations directly performed on plaintext data unable to be realized on ciphertext, and ciphertext retrieval becomes difficult. For users, data retrieval is an essential operation, such as pulling personal photos on the network, password matching for logging in to websites, etc. If the efficiency is too low, it is unacceptable to users. Therefore, it has important research significance to ensure the security of user data while providing efficient retrieval services. Summary of the Invention

[0005] The main objective of the present invention is to provide a lightweight fully homomorphic encryption scheme applicable to database encryption, which has the advantages of relatively low computational overhead, relatively fast computational speed, and easy implementation.

[0006] To achieve the above objective, the fully homomorphic encryption method applicable to ciphertext encryption proposed in the first aspect of the present invention includes the proxy server performing the following steps:

[0007] Randomly generate two large prime numbers with a preset bit length, and simultaneously generate the current timestamp;

[0008] Generate a public-private key pair based on the two large prime numbers and the timestamp, and the public-private key pair is used to encrypt data for storage in the encrypted database;

[0009] Receive a query request initiated by the user server, where the query request includes a query statement, and the query statement includes query keyword fields, homomorphic calculation types, and calculation objects;

[0010] Encrypt the query keyword fields in the query statement according to the public key of the public-private key pair to obtain an encrypted query statement, and send the encrypted query statement to the encrypted database;

[0011] Receive the query ciphertext from the encrypted database, where the query ciphertext is the corresponding data retrieved by the encrypted database after receiving the encrypted query statement;

[0012] Perform homomorphic calculation on the query ciphertext according to the homomorphic calculation type to obtain a query result;

[0013] Decrypt the query result using the private key to obtain the plaintext of the query result;

[0014] Send the plaintext of the query result to the user server.

[0015] Further, generating a public-private key pair based on the two large prime numbers and the timestamp includes the following steps:

[0016] Multiply the two large prime numbers to obtain the product of the two large prime numbers;

[0017] Take any one of the large prime numbers as the private key, use the current timestamp as the base, and the large prime number as the private key as the exponent for power operation to obtain the result of multiplying the large prime number of current timestamps;

[0018] Use the result of multiplying the large prime number of current timestamps as the dividend, and the product of the two large prime numbers as the divisor for modulo operation to obtain the first remainder;

[0019] Take the first remainder, the large prime number as the private key, and the product of the two large prime numbers as the public key.

[0020] Further, encrypting the query keyword fields in the query statement according to the public key of the public-private key pair includes the following steps:

[0021] Identify the query keyword fields in the query statement;

[0022] When the query keyword fields satisfy the plaintext value range, sum the query keyword fields with the product of a large prime number and a first remainder serving as the private key to obtain a summation result;

[0023] Use the summation result as the dividend and the product of two large prime numbers as the divisor to perform a modulo operation to obtain a second remainder, and the second remainder is the encrypted keyword field.

[0024] Further, obtaining the encrypted query statement includes the following steps:

[0025] Convert the query keyword fields in the query statement into encrypted keyword fields;

[0026] Split the query statement with encrypted keyword fields according to the calculation object to obtain multiple encrypted query statements corresponding one by one to the query objects.

[0027] Further, decrypting the query result using the private key includes: using the query result as the dividend and the large prime number serving as the private key as the divisor to perform a modulo operation to obtain a third remainder.

[0028] The second aspect of the present invention discloses a fully homomorphic encryption system applicable to ciphertext encryption, including:

[0029] A key generation module, used to randomly generate two large prime numbers with a preset bit length, and at the same time generate a current timestamp; also used to generate a public-private key pair according to the two large prime numbers and the timestamp, and the public-private key pair is used to encrypt data for storage in an encrypted database;

[0030] A request receiving module, used to receive a query request initiated by a user server, and the query request includes a query statement, and the query statement includes query keyword fields, a homomorphic calculation type, and a calculation object;

[0031] A request encryption module, used to encrypt the query keyword fields in the query statement according to the public key of the public-private key pair to obtain an encrypted query statement, and send the encrypted query statement to the encrypted database;

[0032] A ciphertext receiving module, used to receive a query ciphertext from the encrypted database, and the query ciphertext is the corresponding data retrieved by the encrypted database after receiving the encrypted query statement;

[0033] A homomorphic computing module, which is used to perform homomorphic computing on the query ciphertext according to the type of homomorphic computing to obtain a query result; specifically, the homomorphic computing module includes an addition unit, a multiplication unit, and a size comparison unit. The addition unit is used to process homomorphic addition computing. The multiplication unit is used to process homomorphic multiplication computing. The size comparison unit is used to process size comparison computing.

[0034] A decryption module, which is used to decrypt the query result using the private key to obtain the plaintext of the query result;

[0035] A sending module, which is used to send the plaintext of the query result to the user server.

[0036] Furthermore, the key generation module includes:

[0037] A first computing unit, which is used to multiply two large prime numbers to obtain the product of the two large prime numbers;

[0038] A private key generation unit, which is used to take any one of the large prime numbers as the private key;

[0039] A second computing unit, which is used to perform a power operation with the current timestamp as the base and the large prime number used as the private key as the exponent to obtain the result of multiplying the large prime number by the current timestamp;

[0040] A third computing unit, which is used to perform a modulo operation with the result of multiplying the large prime number by the current timestamp as the dividend and the product of the two large prime numbers as the divisor to obtain a first remainder;

[0041] A public key generation unit, which is used to take the first remainder, the large prime number used as the private key, and the product of the two large prime numbers as the public key.

[0042] Furthermore, the request encryption module includes:

[0043] An identification unit, which is used to identify the query keyword field in the query statement;

[0044] A fourth computing unit, which is used to sum the query keyword field with the product of the large prime number used as the private key and the first remainder when the query keyword field meets the plaintext value range to obtain a summation result;

[0045] A fifth computing unit, which is used to perform a modulo operation with the summation result as the dividend and the product of the two large prime numbers as the divisor to obtain a second remainder, and the second remainder is the encrypted keyword field.

[0046] A third aspect of the present invention discloses a fully homomorphic encryption device applicable to ciphertext encryption, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the method described in any one of the first aspects of the present invention is implemented.

[0047] A fourth aspect of the present invention discloses a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, the method described in any one of the first aspects of the present invention is implemented.

[0048] The technical solution provided by the present invention may include the following beneficial effects:

[0049] In the fully homomorphic encryption method suitable for ciphertext encryption provided by the present invention, the proxy server generates a public key pair and encrypts the data and stores it in the terminal database. When the application server needs to query the sum or product of multiple fields or compare the fields, a query request is initiated to the proxy server; the proxy server receives the request from the application server, encrypts the key fields of the user's query statement, and still ensures the grammatical requirements of the query statement, and sends the encrypted query statement to the encryption database; the terminal database receives the query statement, retrieves the field record ciphertext and sends it to the proxy server; the proxy server receives the ciphertext data returned from the terminal database, and performs addition, multiplication or comparison operations on the ciphertext data according to the query statement requirements, and decrypts the operation results and sends them to the application server.

[0050] The existing fully homomorphic algorithms require algebraic operations based on group ring fields, while the fully homomorphic encryption method suitable for ciphertext encryption provided by the present invention only requires simple large integer operations, has the advantages of low computational overhead, fast computational speed and easy implementation, and realizes efficient data retrieval without the need for users to wait for a long time. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the structures shown in these drawings without paying creative work.

[0052] Figure 1 It is a flow chart of a fully homomorphic encryption method applicable to ciphertext encryption of the present invention;

[0053] Figure 2 It is an interaction diagram of the fully homomorphic encryption method applicable to ciphertext encryption of the present invention;

[0054] Figure 3 It is a schematic diagram of the structure of a fully homomorphic encryption system applicable to ciphertext encryption of the present invention;

[0055] Figure 4 It is a schematic diagram of the structure of a fully homomorphic encryption device suitable for ciphertext encryption according to the present invention. DETAILED DESCRIPTION

[0056] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0057] It should be noted that all directional indications (such as up, down, left, right, front, back,...) in the embodiments of the present invention are only used to explain the relative position relationship, movement conditions, etc. between components in a specific posture (as shown in the accompanying drawings). If the specific posture changes, the directional indications will also change accordingly.

[0058] In the present invention, unless otherwise clearly defined and limited, terms such as "connection" and "fixation" shall be understood in a broad sense. For example, "fixation" can be a fixed connection, a detachable connection, or integrated; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two components or the interaction relationship between two components, unless otherwise clearly limited. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.

[0059] In addition, in the present invention, descriptions such as "first" and "second" are only for descriptive purposes and cannot be understood as indicating or implying their relative importance or implicitly indicating the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include at least one such feature. In addition, the meaning of "and / or" appearing throughout the text is that it includes three parallel solutions. Taking "A and / or B" as an example, it includes solution A, solution B, or a solution that satisfies both A and B. In addition, the technical solutions between the various embodiments can be combined with each other, but it must be based on the ability of those of ordinary skill in the art to implement. When the combination of technical solutions results in contradictions or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the protection scope required by the present invention.

[0060] The system of the specific application of the present invention includes an application server, a proxy server and an encrypted database. The encrypted database is used to store encrypted data. The proxy server generates a public key pair and encrypts the data and stores it in the terminal database. When the application server needs to query the sum or product of multiple fields or compare the fields, it initiates a query request to the proxy server; the proxy server receives the request from the application server, encrypts the key fields of the user's query statement, and still ensures the grammatical requirements of the query statement, and sends the encrypted query statement to the encrypted database; the terminal database receives the query statement, retrieves the field record ciphertext and sends it to the proxy server; the proxy server receives the ciphertext data returned from the terminal database, and performs addition, multiplication or comparison operations on the ciphertext data according to the query statement requirements, and decrypts the operation results and sends them to the application server.

[0061] Specifically, the following Figure 1 , describing a fully homomorphic encryption method applicable to ciphertext encryption according to an embodiment of the present invention,

[0062] Including the proxy server performs the following steps:

[0063] Step S1: randomly generate two large prime numbers of preset bit lengths and generate the current timestamp at the same time; specifically, two large prime numbers can be randomly generated according to the input security parameters. The security parameters include the number of large prime numbers generated and the preset bit length of the large prime numbers. More specifically, in one embodiment of the invention, the input security parameters (2, l ), randomly generate two lbits Large prime number of length p , q .

[0064] Step S2: Generate a public-private key pair according to two large prime numbers and a timestamp, wherein the public-private key pair is used to encrypt data for storage in an encrypted database.

[0065] Specifically, generating a public-private key pair based on two large prime numbers and a timestamp includes the following steps:

[0066] Step S21: multiply two large prime numbers to obtain the product of the two large prime numbers;

[0067] Step S22: Take any large prime number as the private key, use the current timestamp as the base, and perform a power operation with the large prime number as the private key as the exponent to obtain the multiplication result of the large prime number and the current timestamp;

[0068] Step S23: taking the multiplication result of the large prime number and the current timestamp as the dividend and the product of the two prime numbers as the divisor to perform a modular operation to obtain a first remainder;

[0069] Step S24: Take the first remainder, the large prime number used as the private key, and the product of the two large prime numbers as the public key.

[0070] That is, in step S2, the two large prime numbers and the current timestamp are calculated according to the following formulas (1) and (2) to obtain the public key and the private key:

[0071] Formula (1);

[0072] Formula (2);

[0073] Among them, n is the product of the two large prime numbers, p is the large prime number used as the private key, q is the other large prime number, r is the first remainder, timestamp is the current timestamp, timestamp p is the p power of the current timestamp. Correspondingly, the public key of the public-private key pair is p k ( p , r , n ), and the private key is s k ( p ).

[0074] For example: The following table (1) is the data table Student that needs to be stored in the encrypted database:

[0075]

[0076] The proxy server encrypts the fields according to the public key p k ( p , r , n ) to obtain the following table (2), and Table (2) is the data table Student stored in the encrypted database after encryption.

[0077]

[0078] Step S3: Receive a query request initiated by the user server. The query request includes a query statement, and the query statement includes a query keyword field, a homomorphic calculation type, and a calculation object;

[0079] Taking Table (1) and Table (2) as an example, for example: The query statement is:

[0080] SELECT Name,Sources1+Sources2 From Student WHERE Age >16;

[0081] Among them, "16" is the query keyword field of this query statement, and Sources1+Sources2 is the addition calculation in the homomorphic calculation type; Sources1 and Sources2 are the calculation objects. The query statement can be understood as: find people whose age is greater than 16 years old from the Student table, and output their names and the sum of Score 1 and Score 2.

[0082] Step S4: Encrypt the keyword field in the query statement according to the public key of the public-private key pair to obtain an encrypted query statement, and send the encrypted query statement to the encrypted database;

[0083] Step S41: Identify the query keyword field in the query statement; specifically, according to the example of the above query statement, identify "16" as the query keyword field.

[0084] Step S42: When the query keyword field satisfies the plaintext value range, sum the query keyword field with the product of the large prime number and the first remainder used as the private key to obtain a summation result;

[0085] Step S43: Use the summation result as the dividend and the product of the two large prime numbers as the divisor to perform a modulo operation to obtain a second remainder, and the second remainder is the encrypted keyword field.

[0086] An example is given for steps S42 and S43. Specifically, the query keyword field "16" can be judged, where m is the unencrypted query keyword field to determine whether the query keyword field satisfies the plaintext value range. If it exceeds the plaintext value range, it is necessary to segment and pad and then perform encryption calculation. When the above conditions are met, the query keyword field is calculated according to formula (3) to obtain the encrypted keyword field:

[0087] Formula (3);

[0088] Among them, c is the encrypted keyword field, m is the unencrypted query keyword field, n is the product of the two large prime numbers, p is the large prime number used as the private key, r is the first remainder.

[0089] More specifically, the query keyword field "16" is encrypted as "86691299036136340305573900146953" after being operated according to formula (3).

[0090] Step S44: Convert the query keyword fields in the query statement into encrypted keyword fields; that is, the query statement is:

[0091] SELECT Name,Sources1+Sources2 From Student WHERE Age >86691299036136340305573900146953;

[0092] Step S45: Split the query statement with encrypted keyword fields according to the calculation object to obtain multiple encrypted query statements corresponding one by one to the query objects.

[0093] Since the encrypted database does not have the ability to calculate large prime numbers, the query statement is disassembled according to the calculation object to obtain:

[0094] The first query statement: SELECT Name,Sources1 From Student WHERE Age >86691299036136340305573900146953; It can be understood as: Find the people whose age is greater than 16 years old from the Student table, and output their names and scores 1;

[0095] The second query statement: SELECT Name,Sources2 From Student WHERE Age >86691299036136340305573900146953; It can be understood as: Find the people whose age is greater than 16 years old from the Student table, and output their names and scores 2.

[0096] According to the above example, it can be seen that in the embodiments of the present invention, if there are N calculation objects in the query statement, then N corresponding encrypted query statements will be split, where N is a positive integer greater than 2;

[0097] Among them, only one calculation object is retained in the query statement during the splitting process, and the homomorphic calculation request and other calculation objects are deleted. This ensures the syntax requirements of the query statement.

[0098] The encrypted database can retrieve the encrypted data corresponding to score 1 of students whose age is greater than 16 according to the first query statement. The encrypted database can retrieve the encrypted data corresponding to score 2 of students whose age is greater than 16 according to the second query statement.

[0099] Step S5: Receive the query ciphertext from the encrypted database. The query ciphertext is the corresponding data retrieved by the encrypted database after receiving the encrypted query statement. That is, the proxy server receives the encrypted data corresponding to the scores 1 of students over 16 years old and the encrypted data corresponding to the scores 2 of students over 16 years old retrieved by the encrypted database.

[0100] Step S6: Perform homomorphic calculation on the query ciphertext according to the type of homomorphic calculation to obtain the query result. Specifically, the types of homomorphic calculation include addition calculation, multiplication calculation, and size comparison calculation.

[0101] Step S7: Decrypt the query result using the private key to obtain the plaintext of the query result.

[0102] Specifically, use the query result as the dividend and the large prime number serving as the private key as the divisor to perform modulo operation to obtain the third remainder. That is, calculate according to formula 4 for the query result.

[0103] Formula (4);

[0104] Among them, is the plaintext of the query result, that is, the decryption result, is the query result, .

[0105] Among them, for the plaintext of the query result , there is:

[0106] Formula (5);

[0107] That is, for the decryption result, if , then it is determined that the result is the original result and return , if , then it is determined that the result is negative and calculate and return .

[0108] More specifically, taking addition as an example:

[0109] The query ciphertext obtained according to the first query statement is , , is the unencrypted first plaintext; the query ciphertext obtained by the second query statement is , = ; is the unencrypted second plaintext.

[0110] The homomorphic addition calculation is:

[0111] Formula (6);

[0112] Among them, The query result after homomorphic addition calculation.

[0113] Among them, the decryption result of is proved as follows:

[0114] Formula (7);

[0115] Formula (8);

[0116] Q.E.D. That is, there exists a homomorphic addition that meets the requirements of homomorphic addition calculation.

[0117] More specifically, taking multiplication as an example: The query ciphertext obtained according to the first query statement is , , is the unencrypted first plaintext; The query ciphertext obtained according to the second query statement is , = ; is the unencrypted second plaintext.

[0118] The homomorphic multiplication calculation is:

[0119] Formula (9);

[0120] Among them, is the query result after homomorphic multiplication calculation.

[0121] Among them, the decryption result of is proved as follows:

[0122] Formula (10);

[0123] Formula (11);

[0124] Q.E.D. That is, there exists a homomorphic multiplication that meets the requirements of homomorphic multiplication calculation.

[0125] More specifically, taking size comparison as an example: The query ciphertext obtained according to the first query statement is , , is the unencrypted first plaintext; The query ciphertext obtained according to the second query statement is , = ; is the unencrypted second plaintext.

[0126] The size comparison calculation is:

[0127] Formula (12);

[0128] where is the difference between the two ciphertexts, and the decryption result is judged If it holds, then return The value of is greater than Otherwise, return The value of is greater than .

[0129] The following proof is made:

[0130] Formula (13);

[0131] Formula (14);

[0132] Formula (15);

[0133] Formula (16);

[0134] To sum up, the decryption result is compared with 0. If the decryption result can be obtained Otherwise .

[0135] Q.E.D.

[0136] Step S8: Send the plaintext of the query result to the user server.

[0137] Existing fully homomorphic algorithms are based on algebraic operations of group rings and fields, while the fully homomorphic encryption method suitable for ciphertext encryption provided by the present invention only requires simple large integer operations, has the advantages of small computational overhead, fast computational speed and easy implementation, realizes efficient data retrieval, and does not require users to wait for a long time.

[0138] The second aspect of the present invention discloses a fully homomorphic encryption system 300 suitable for ciphertext encryption, including:

[0139] A key generation module 301, configured to randomly generate two large prime numbers with a preset bit length, and simultaneously generate a current timestamp; and further configured to generate a public-private key pair according to the two large prime numbers and the timestamp, where the public-private key pair is used to encrypt data for storage in an encrypted database;

[0140] A request receiving module 302, configured to receive a query request initiated by a user server, where the query request includes a query statement, and the query statement includes a query keyword field, a homomorphic calculation type, and a calculation object;

[0141] A request encryption module 303, configured to encrypt a keyword field in a query statement according to the public key of a public-private key pair to obtain an encrypted query statement, and send the encrypted query statement to an encrypted database;

[0142] A ciphertext receiving module 304, configured to receive a query ciphertext from the encrypted database, where the query ciphertext is the corresponding data retrieved by the encrypted database after receiving the encrypted query statement;

[0143] A homomorphic computing module 305, configured to perform homomorphic computing on the query ciphertext according to the type of homomorphic computing to obtain a query result;

[0144] A decryption module 306, configured to decrypt the query result using the private key to obtain a plaintext query result;

[0145] A sending module 307, configured to send the plaintext query result to a user server.

[0146] Further, the key generation module 301 includes:

[0147] A parameter generation unit, configured to randomly generate two large prime numbers with a preset bit length, and simultaneously generate a current timestamp;

[0148] A first calculation unit, configured to multiply the two large prime numbers to obtain a product of the two large prime numbers;

[0149] A private key generation unit, configured to take any one of the large prime numbers as the private key;

[0150] A second calculation unit, configured to perform a power operation with the current timestamp as the base and the large prime number used as the private key as the exponent to obtain a result of multiplying the large prime number by the current timestamp;

[0151] A third calculation unit, configured to perform a modulo operation with the result of multiplying the large prime number by the current timestamp as the dividend and the product of the two large prime numbers as the divisor to obtain a first remainder;

[0152] A public key generation unit, configured to take the first remainder, the large prime number used as the private key, and the product of the two large prime numbers as the public key.

[0153] Further, the request encryption module 303 includes:

[0154] An identification unit, configured to identify a query keyword field in a query statement;

[0155] A fourth calculation unit, configured to, when the query keyword field meets the plaintext value range, sum the query keyword field with the product of the large prime number used as the private key and the first remainder to obtain a sum result;

[0156] A fifth calculation unit, configured to perform a modulo operation with the sum result as the dividend and the product of two large prime numbers as the divisor to obtain a second remainder, where the second remainder is an encrypted key field.

[0157] Further, the request encryption module 303 further includes:

[0158] An encryption unit, configured to convert a query key field in a query statement into an encrypted key field;

[0159] A splitting unit, configured to split the query statement with the encrypted key field according to a calculation object to obtain a plurality of encrypted query statements corresponding to the query objects one by one.

[0160] Further, the decryption module 306 includes:

[0161] A sixth calculation unit, configured to perform a modulo operation with the query result as the dividend and a large prime number as the private key as the divisor to obtain a third remainder.

[0162] It should be noted that the fully homomorphic encryption system 300 applicable to ciphertext encryption provided in the embodiments of the present invention may be built on a proxy server, and each of the above units and modules may refer to program modules or units. In addition, for more details and corresponding technical effects of the system in the embodiments of the present invention, reference may be made to the description of the method embodiments above, and details will not be repeated here.

[0163] The system in the embodiments of the present invention described above can be used to execute the corresponding method embodiments in the present invention, and correspondingly achieve the technical effects achieved by the method embodiments of the present invention, which will not be repeated here.

[0164] Such as Figure 4As shown in the figure, on the other hand, the present invention discloses a fully homomorphic encryption device 400 applicable to ciphertext encryption, including: a processor 401 and a memory 402. Among them, the processor 401 and the memory 402 are connected, such as connected through a bus 403. Further, the fully homomorphic encryption device 400 applicable to ciphertext encryption may further include a transceiver 404. It should be noted that in practical applications, the transceiver 404 is not limited to one, and the structure of the fully homomorphic encryption device 400 applicable to ciphertext encryption does not constitute a limitation to the embodiments of the present application. Among them, the processor 401 is applied in the embodiments of the present application to implement the functions of each unit and module of the fully homomorphic encryption system applicable to ciphertext encryption. The processor 401 may be a CPU, a general-purpose processor, a DSP, an ASIC, an FPGA or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. It can implement or execute various exemplary logic blocks, modules and circuits described in combination with the disclosed content of the present application. The processor 401 may also be a combination that realizes computing functions, such as a combination including one or more microprocessors, a combination of a DSP and a microprocessor, etc. The bus 403 may include a path for transmitting information between the above components. The bus 403 may be a PCI bus or an EISA bus, etc. The bus 403 may be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 4 only a thick line is used to represent it in the figure, but it does not mean that there is only one bus or one type of bus. The memory 402 may be a ROM or other type of static storage device that can store static information and instructions, a RAM or other type of dynamic storage device that can store information and instructions, or an EEPROM, a CD-ROM or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 402 is used to store the application program code for executing the solution of the present application and is controlled by the processor 401 to execute. The processor 401 is used to execute the application program code stored in the memory 402 to implement the fully homomorphic encryption method applicable to ciphertext encryption provided by the present invention.

[0165] On the other hand, an embodiment of the present invention provides a storage medium, on which a computer program is stored, and the program is executed by a processor to perform the steps of the fully homomorphic encryption method applicable to ciphertext encryption as executed by the above server.

[0166] The above products can execute the methods provided by the embodiments of the present application and have the corresponding functional modules and beneficial effects of the executed methods. For the technical details not described in detail in this embodiment, reference can be made to the methods provided by the embodiments of the present application.

[0167] The optional implementation manners of the embodiments of the present invention have been described in detail above in conjunction with the accompanying drawings. However, the embodiments of the present invention are not limited to the specific details in the above embodiments. Within the scope of the technical concept of the embodiments of the present invention, various simple modifications can be made to the technical solutions of the embodiments of the present invention, and these simple modifications all fall within the protection scope of the embodiments of the present invention.

[0168] In addition, it should be noted that, in the above specific implementation manners, the various specific technical features described can be combined in any appropriate manner without conflict. To avoid unnecessary repetition, the embodiments of the present invention will not separately describe various possible combination manners.

[0169] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structural transformation made by using the content of the specification and drawings of the present invention under the concept of the present invention, or directly / indirectly applied in other related technical fields, is included in the patent protection scope of the present invention.

Claims

1. A fully homomorphic encryption method suitable for ciphertext encryption, characterized by: Including the proxy server performs the following steps: Randomly generate two large prime numbers with preset bit lengths and generate the current timestamp at the same time; Generate a public-private key pair based on two large prime numbers and a timestamp, wherein the public-private key pair is used to encrypt data for storage in an encrypted database; Receiving a query request initiated by a user server, the query request including a query statement, the query statement including a query key field, a homomorphic computing type, and a computing object; Encrypting a query key field in the query statement according to the public key of the public-private key pair to obtain an encrypted query statement, and sending the encrypted query statement to an encryption database; Receiving a query ciphertext from an encrypted database, wherein the query ciphertext is corresponding data retrieved by the encrypted database after receiving the encrypted query statement; Perform homomorphic computation on the query ciphertext according to the type of homomorphic computation to obtain the query result; Decrypt the query result using the private key to obtain the plain text of the query result; Sending the query result in plain text to the user server; Among them, generating a public-private key pair based on two large prime numbers and a timestamp includes the following steps: Multiply two large prime numbers to get the product of the two large prime numbers; Take any large prime number as the private key, use the current timestamp as the base, and perform a power operation with the large prime number as the exponent to get the multiplication result of the large prime number and the current timestamp; Use the result of multiplying the current timestamp by a large prime number as the dividend, and the product of the two prime numbers as the divisor to perform a modulo operation to obtain the first remainder; Take the first remainder, the large prime number used as the private key, and the product of two large prime numbers as the public key.

2. The fully homomorphic encryption method suitable for ciphertext encryption according to claim 1, characterized in that: Encrypting the query key field in the query statement using the public key of the public-private key pair includes the following steps: Identify the query key fields in the query statement; When the query key field meets the plaintext value range, the query key field and the product of the large prime number as the private key and the first remainder are summed to obtain a sum result; A modular operation is performed with the sum result as the dividend and the product of the two prime numbers as the divisor to obtain a second remainder, where the second remainder is an encryption key field.

3. The fully homomorphic encryption method suitable for ciphertext encryption according to claim 2, characterized in that: Obtaining the encrypted query statement includes the following steps: Convert the query key field in the query statement into an encrypted key field; The query statement with the encrypted key field is split according to the calculation object to obtain multiple encrypted query statements corresponding to the query objects one by one.

4. The fully homomorphic encryption method suitable for ciphertext encryption according to claim 1, characterized in that: Decrypting the query result using the private key includes: performing a modulo operation using the query result as a dividend and a large prime number serving as the private key as a divisor to obtain a third remainder.

5. A fully homomorphic encryption system suitable for ciphertext encryption, characterized by: include: The key generation module is used to randomly generate two large prime numbers with preset bit lengths and generate the current timestamp; Also used to generate a public-private key pair based on two large prime numbers and a timestamp, wherein the public-private key pair is used to encrypt data for storage in an encrypted database; A request receiving module, used to receive a query request initiated by a user server, wherein the query request includes a query statement, and the query statement includes a query key field, a homomorphic computing type, and a computing object; A request encryption module is used to encrypt the query key field in the query statement according to the public key of the public-private key pair to obtain an encrypted query statement, and send the encrypted query statement to the encryption database; A ciphertext receiving module, used to receive a query ciphertext from an encrypted database, wherein the query ciphertext is corresponding data retrieved after the encrypted database receives the encrypted query statement; A homomorphic computing module is used to perform homomorphic computing on the query ciphertext according to the homomorphic computing type to obtain the query result; A decryption module is used to decrypt the query result using a private key to obtain the query result in plain text; A sending module, used for sending the query result in plain text to a user server; Among them, the key generation module includes: A first calculation unit is used for multiplying two large prime numbers to obtain the product of the two large prime numbers; A private key generation unit, used to take any large prime number as a private key; The second calculation unit is used to perform a power operation with the current timestamp as the base and the large prime number as the private key as the exponent to obtain a multiplication result of the large prime number and the current timestamp; A third calculation unit is used for performing a modulo operation using a multiplication result of a large prime number and a current timestamp as a dividend and a product of the two prime numbers as a divisor to obtain a first remainder; The public key generation unit is used to take the first remainder, the large prime number used as the private key and the product of two large prime numbers as the public key.

6. The fully homomorphic encryption system suitable for ciphertext encryption according to claim 5, characterized in that: The request encryption module includes: An identification unit, used for identifying a query key field in a query statement; A fourth calculation unit is used to sum the query key field with the product of the large prime number as the private key and the first remainder to obtain a sum result when the query key field meets the plaintext value range; The fifth calculation unit is used to perform a modular operation with the sum result as the dividend and the product of the two prime numbers as the divisor to obtain a second remainder, where the second remainder is an encryption key field.

7. A fully homomorphic encryption device suitable for ciphertext encryption, characterized in that: The method comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the method according to any one of claims 1 to 4 is implemented.

8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the method according to any one of claims 1 to 4.